""ET TROJAN OSX/OceanLotus / ELF/RotaJakario CnC Checkin""

SID: 2024425

Revision: 1

Class Type: trojan-activity

Metadata: affected_product Mac_OSX, attack_target Client_Endpoint, created_at 2017_06_26, deployment Perimeter, malware_family OceanLotus, performance_impact Low, tag Targeted, tag APT, tag OceanLotus, tag OSX, updated_at 2017_06_26

Reference:

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: any

Flow: established,to_server

Contents:

  • Value: "|41 61 54 03|" Depth: 4 Offset: 1

  • Value: "|63 63 63 63 63 63 63 63|"

Within:

PCRE:

Special Options:

  • fast_pattern

source